Microsoft Outlook Will Block .MSIX and .MSIXBUNDLE Attachments
Microsoft is adding .msix and .msixbundle files to the list of attachments blocked by Outlook on the web and the new Outlook for Windows client.
The change will begin rolling out to Exchange Online users in early November, when Microsoft adds the two file types to the BlockedFileTypes list in all Outlook on the web mailbox policies. The update is expected to become generally available by mid-November.
Outlook will block MSIX installation packages
An .msix file is a modern Windows installation package designed for a specific computer architecture or configuration. An .msixbundle file is a container that combines multiple MSIX packages into a single file compatible with multiple computer architectures.
After the policy update, .msix and .msixbundle attachments will be blocked by default. Users of Outlook on the web and the new Outlook for Windows will not be able to send, receive, open, or download these attachments.
Microsoft said the change is intended to improve the security of Outlook on the web and the new Outlook for Windows by updating the default file types blocked by the OwaMailboxPolicy.
“As part of this update, .msix and .msixbundle file types will be added to the BlockedFileTypes list in the default OWA mailbox policy and any custom policies created in your tenant,” Microsoft said in a Microsoft 365 Message Center update.
Microsoft 365 administrators can allow MSIX files
Organizations that do not use .msix or .msixbundle files will not need to take any action. Administrators can optionally allow the file types by adding them to the AllowedFileTypes property of a user’s OwaMailboxPolicy object.
“Because these file types are used infrequently, we do not expect most organizations to be affected by this update,” Microsoft added. “This update is part of our ongoing efforts to strengthen security and protect organizations from potentially unsafe attachments.”
Outlook continues blocking file types used in attacks
The move is part of Microsoft’s broader effort to disable or remove Office and Windows features that attackers have exploited in attacks against Microsoft customers.
In June 2025, Outlook began blocking .library-ms and .search-ms files. Attackers had exploited those file types in phishing and malware attacks, including campaigns targeting government agencies, since at least June 2022.
More recently, in October 2025, Microsoft announced that Outlook on the web and the new Outlook for Windows would stop displaying dangerous inline SVG images, which have also been used in attacks.
A complete list of attachments that Exchange Server and Exchange Online users cannot save or view in Outlook on the web is available in the Microsoft documentation.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



